993 vulnerabilities patched by Microsoft in the September 2026 Patch Tuesday release.
Severity Breakdown
- Critical: 132
- Important: 861
Actively Exploited (2)
CVE-2026-81963 — Windows Update Stack Elevation of Privilege Vulnerability
CVSS 7.8 | Windows Update Stack | Actively Exploited
CVE-2026-85880 — Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
CVSS 7.8 | Windows ALPC | Actively Exploited
Exploitation More Likely (58)
- CVE-2026-69525 — Remote Desktop Services Remote Code Execution Vulnerability (CVSS 9.8, Windows Remote Desktop Services)
- CVE-2026-69730 — Windows DNS Server Remote Code Execution Vulnerability (CVSS 9.8, Windows DNS)
- CVE-2026-69854 — Spring Cloud Azure Elevation of Privilege Vulnerability (CVSS 9.0, Spring Cloud Azure)
- CVE-2026-69676 — Windows Kerberos Remote Code Execution Vulnerability (CVSS 8.8, Windows Kerberos)
- CVE-2026-72940 — Windows Schannel Remote Code Execution Vulnerability (CVSS 8.8, Windows Schannel)
- CVE-2026-69857 — Azure Cosmos DB Spoofing Vulnerability (CVSS 8.5, Azure Cosmos DB)
- CVE-2026-70342 — Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVSS 8.1, Windows Ancillary Function Driver for WinSock)
- CVE-2026-72936 — Windows SMB Client Remote Code Execution Vulnerability (CVSS 8.1, Windows SMB Client)
- CVE-2026-68876 — Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability (CVSS 8.0, Windows Program Compatibility Assistant Service)
- CVE-2026-68880 — Windows Win32k Elevation of Privilege Vulnerability (CVSS 8.0, Windows Win32K)
- CVE-2026-69301 — Windows Win32k Elevation of Privilege Vulnerability (CVSS 8.0, Windows Win32K)
- CVE-2026-69623 — Windows HTTP Print Provider Remote Code Execution Vulnerability (CVSS 8.0, Windows HTTP Print Provider)
- CVE-2026-69714 — Windows Device Association Service Elevation of Privilege Vulnerability (CVSS 8.0, Windows Device Association Service)
- CVE-2026-69777 — Windows DHCP Client Elevation of Privilege Vulnerability (CVSS 8.0, Windows DHCP Client)
- CVE-2026-69277 — Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability (CVSS 7.8, Microsoft Local Security Authority Server (lsasrv))
- CVE-2026-69391 — Windows Broker Infrastructure Service Elevation of Privilege Vulnerability (CVSS 7.8, Windows Broker Infrastructure Service)
- CVE-2026-69436 — Windows State Repository Service Elevation of Privilege Vulnerability (CVSS 7.8, Windows State Repository Service)
- CVE-2026-69450 — Windows Error Reporting Elevation of Privilege Vulnerability (CVSS 7.8, Windows Error Reporting)
- CVE-2026-69459 — Windows Power Dependency Coordinator Elevation of Privilege Vulnerability (CVSS 7.8, Windows Power Dependency Coordinator)
- CVE-2026-69467 — Microsoft Graphics Component Elevation of Privilege Vulnerability (CVSS 7.8, Microsoft Graphics Component)
- +38 more
Executive Summary
Microsoft’s September 2026 Patch Tuesday is one of the largest on record, addressing 993 vulnerabilities across the Windows ecosystem, Azure cloud services, Office suite, SQL Server, and numerous supporting components. Of these, 132 are rated Critical and 58 carry Microsoft’s “Exploitation More Likely” designation, signaling a broad and urgent patching cycle. Two vulnerabilities are confirmed under active exploitation: CVE-2026-81963, an elevation of privilege in the Windows Update Stack, and CVE-2026-85880, an elevation of privilege in Windows ALPC. Both carry a CVSS score of 7.8 and provide local privilege escalation, meaning they are likely being chained with initial access vectors in real-world attacks. These two zero-days should be treated as the highest priority for endpoint teams, particularly on systems where standard users operate and lateral movement risk is elevated.
On the cloud and identity side, this release contains an extraordinary cluster of CVSS 10.0 elevation of privilege vulnerabilities spanning Azure Billing, Azure Arc, Microsoft Fabric, Azure Container Registry, Azure Logic Apps, Azure AI Language, Azure AD B2C, and Azure AI Foundry. A separate Entra ID flaw scores 9.9. While many of these are service-side issues that Microsoft may remediate without customer action, security teams running hybrid or self-managed Azure Arc deployments should verify their update status immediately. The Entra ID vulnerability in particular warrants attention from identity and access management teams given its potential to compromise authentication trust boundaries. Organizations should confirm with Microsoft advisories whether any of these require tenant-level configuration changes or customer-side patching.
The on-premises attack surface is equally significant. SQL Server accounts for 61 vulnerabilities including 5 critical, making it a priority for database administrators. Microsoft Office products are heavily affected, with Excel carrying 6 critical flaws and Word carrying 2, creating substantial risk from weaponized documents delivered via email or collaboration platforms. Windows DHCP Server has 36 patches including 2 critical, and Windows DNS has 14 patches with 4 critical — both are infrastructure services that should be patched in the next maintenance window. The Windows Biometric Service leads in raw volume at 64 fixes, though none are critical.
Given the scale of this release, security teams should triage in three waves. First, patch the two actively exploited zero-days on all Windows endpoints without delay. Second, coordinate with cloud and identity teams to validate exposure to the CVSS 10.0 Azure and Entra ID vulnerabilities and confirm remediation status. Third, schedule infrastructure patching for DNS, DHCP, and SQL Server, and push Office updates through your standard deployment channels with urgency given the critical document-parsing flaws. With 58 vulnerabilities flagged as “Exploitation More Likely,” the window between patch availability and weaponization will be short.
Critical Vulnerabilities
Azure Billing (1 Critical)
- CVE-2026-62874 — Azure Billing Elevation of Privilege Vulnerability (CVSS 10.0) Advisory
Azure Arc (2 Critical)
- CVE-2026-69399 — Azure Arc Elevation of Privilege Vulnerability (CVSS 10.0) Advisory
- CVE-2026-70009 — Azure Arc Elevation of Privilege Vulnerability (CVSS 9.3) Advisory
Microsoft Fabric (2 Critical)
- CVE-2026-69843 — Microsoft Fabric Elevation of Privilege Vulnerability (CVSS 10.0) Advisory
- CVE-2026-70178 — Microsoft Fabric Elevation of Privilege Vulnerability (CVSS 8.5) Advisory
Microsoft Container Registry (1 Critical)
- CVE-2026-69865 — Microsoft Container Registry Elevation of Privilege Vulnerability (CVSS 10.0) Advisory
Azure Logic Apps (2 Critical)
- CVE-2026-70200 — Azure Logic Apps Elevation of Privilege Vulnerability (CVSS 10.0) Advisory
- CVE-2026-83944 — Azure Logic Apps Elevation of Privilege Vulnerability (CVSS 10.0) Advisory
Azure AI Language (1 Critical)
- CVE-2026-70352 — Azure AI Language Elevation of Privilege Vulnerability (CVSS 10.0) Advisory
Microsoft Azure Active Directory B2C (1 Critical)
- CVE-2026-83711 — Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability (CVSS 10.0) Advisory
Azure AI Foundry (2 Critical)
- CVE-2026-85889 — Azure AI Foundry Elevation of Privilege Vulnerability (CVSS 10.0) Advisory
- CVE-2026-85917 — Azure AI Foundry Elevation of Privilege Vulnerability (CVSS 7.5) Advisory
Entra ID (1 Critical)
- CVE-2026-83941 — Entra ID Elevation of Privilege Vulnerability (CVSS 9.9) Advisory
Azure Database for PostgreSQL (1 Critical)
- CVE-2026-85878 — Azure Database for PostgreSQL Elevation of Privilege Vulnerability (CVSS 9.9) Advisory
M365 Copilot (2 Critical)
- CVE-2026-85885 — Microsoft 365 Copilot Elevation of Privilege Vulnerability (CVSS 9.9) Advisory
- CVE-2026-85887 — M365 Copilot Information Disclosure Vulnerability (CVSS 7.7) Advisory
Skype for Business (1 Critical)
- CVE-2026-66302 — Skype for Business Remote Code Execution Vulnerability (CVSS 9.8) Advisory
SQL Server (5 Critical)
- CVE-2026-67631 — Microsoft SQL Server Remote Code Execution Vulnerability (CVSS 9.8) Advisory
- CVE-2026-67643 — Microsoft SQL Server Remote Code Execution Vulnerability (CVSS 9.8) Advisory
- CVE-2026-65669 — Microsoft SQL Server Elevation of Privilege Vulnerability (CVSS 9.6) Advisory
- CVE-2026-67378 — Microsoft SQL Server Remote Code Execution Vulnerability (CVSS 9.0) Advisory
- CVE-2026-67636 — Microsoft SQL Server Remote Code Execution Vulnerability (CVSS 9.0) Advisory
Windows Message Queuing (1 Critical)
- CVE-2026-69579 — Windows Message Queuing Remote Code Execution Vulnerability (CVSS 9.8) Advisory
Windows Routing and Remote Access Service (RRAS) (4 Critical)
- CVE-2026-69590 — Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability (CVSS 9.8) Advisory
- CVE-2026-72950 — Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-72959 — Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-69852 — Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability (CVSS 7.5) Advisory
Windows Services for NFS ONCRPC XDR Driver (3 Critical)
- CVE-2026-69595 — Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability (CVSS 9.8) Advisory
- CVE-2026-78445 — Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability (CVSS 9.8) Advisory
- CVE-2026-70585 — Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability (CVSS 7.0) Advisory
Windows DNS (4 Critical)
- CVE-2026-69730 — Windows DNS Server Remote Code Execution Vulnerability (CVSS 9.8) Advisory
- CVE-2026-69813 — Windows DNS Server Remote Code Execution Vulnerability (CVSS 8.1) Advisory
- CVE-2026-69858 — Windows DNS Server Remote Code Execution Vulnerability (CVSS 8.1) Advisory
- CVE-2026-72987 — Windows DNS Remote Code Execution Vulnerability (CVSS 8.1) Advisory
Windows HTTP Print Provider (1 Critical)
- CVE-2026-69769 — Windows HTTP Print Provider Remote Code Execution Vulnerability (CVSS 9.8) Advisory
Windows Shell (1 Critical)
- CVE-2026-69829 — Windows Shell Remote Code Execution Vulnerability (CVSS 9.8) Advisory
Windows DHCP Server (2 Critical)
- CVE-2026-69845 — Windows DHCP Server Remote Code Execution Vulnerability (CVSS 9.8) Advisory
- CVE-2026-72979 — Windows DHCP Server Remote Code Execution Vulnerability (CVSS 9.8) Advisory
Windows Imaging Component (6 Critical)
- CVE-2026-70296 — Windows Imaging Component Remote Code Execution Vulnerability (CVSS 9.8) Advisory
- CVE-2026-69499 — Windows Imaging Component Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-69860 — Windows Imaging Component Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-73013 — Windows Imaging Component Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-73023 — Windows Imaging Component Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-77495 — Windows Imaging Component Remote Code Execution Vulnerability (CVSS 8.8) Advisory
Windows Netlogon (1 Critical)
- CVE-2026-72982 — Windows Netlogon Remote Code Execution Vulnerability (CVSS 9.8) Advisory
Windows Internet Connection Sharing (ICS) (1 Critical)
- CVE-2026-72983 — Internet Connection Sharing (ICS) Remote Code Execution Vulnerability (CVSS 9.8) Advisory
Windows Secure Socket Tunneling Protocol (SSTP) (1 Critical)
- CVE-2026-73009 — Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability (CVSS 9.8) Advisory
Windows Failover Cluster (2 Critical)
- CVE-2026-73010 — Microsoft Failover Cluster Remote Code Execution Vulnerability (CVSS 9.8) Advisory
- CVE-2026-78444 — Microsoft Failover Cluster Remote Code Execution Vulnerability (CVSS 8.1) Advisory
Microsoft Graphics Component (4 Critical)
- CVE-2026-77493 — Windows Graphics Component Remote Code Execution Vulnerability (CVSS 9.8) Advisory
- CVE-2026-73006 — DirectWrite Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-78439 — Microsoft Office Graphics Component Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-81955 — Windows Graphics Component Remote Code Execution Vulnerability (CVSS 8.8) Advisory
Microsoft Office Outlook (4 Critical)
- CVE-2026-78509 — Microsoft Office Outlook Remote Code Execution Vulnerability (CVSS 9.8) Advisory
- CVE-2026-78519 — Microsoft Office Outlook Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-78525 — Microsoft Office Outlook Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-78520 — Microsoft Office Outlook Information Disclosure Vulnerability (CVSS 6.5) Advisory
Azure Cosmos DB (2 Critical)
- CVE-2026-87701 — Azure Cosmos DB Elevation of Privilege Vulnerability (CVSS 9.6) Advisory
- CVE-2026-69857 — Azure Cosmos DB Spoofing Vulnerability (CVSS 8.5) Advisory
Copilot Studio (1 Critical)
- CVE-2026-80098 — Copilot Studio Elevation of Privilege Vulnerability (CVSS 9.3) Advisory
Microsoft Entra ID (1 Critical)
- CVE-2026-62916 — Microsoft Entra ID Elevation of Privilege Vulnerability (CVSS 9.1) Advisory
Spring Cloud Azure (1 Critical)
- CVE-2026-69854 — Spring Cloud Azure Elevation of Privilege Vulnerability (CVSS 9.0) Advisory
Microsoft Dataverse (1 Critical)
- CVE-2026-77903 — Microsoft Dataverse Elevation of Privilege Vulnerability (CVSS 9.0) Advisory
Microsoft Dynamics 365 (1 Critical)
- CVE-2026-65772 — Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability (CVSS 8.8) Advisory
Microsoft Office (5 Critical)
- CVE-2026-69285 — Microsoft Office Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-69632 — Microsoft Office Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-78505 — Microsoft Office Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-78510 — Microsoft Outlook and Word Remote Code Execution Vulnerability (CVSS 8.4) Advisory
- CVE-2026-77898 — Microsoft Office Remote Code Execution Vulnerability (CVSS 7.5) Advisory
Windows Remote Desktop (1 Critical)
- CVE-2026-69518 — Windows Remote Desktop Remote Code Execution Vulnerability (CVSS 8.8) Advisory
Microsoft Windows Media Foundation (1 Critical)
- CVE-2026-69601 — Microsoft Windows Media Foundation Remote Code Execution Vulnerability (CVSS 8.8) Advisory
Windows Hyper-V (3 Critical)
- CVE-2026-69603 — Windows Hyper-V Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-80083 — Windows Hyper-V Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-72961 — Windows Hyper-V Elevation of Privilege Vulnerability (CVSS 8.2) Advisory
Windows Raw Image Extension (1 Critical)
- CVE-2026-69649 — Raw Image Extension Remote Code Execution Vulnerability (CVSS 8.8) Advisory
Windows Kerberos (1 Critical)
- CVE-2026-69676 — Windows Kerberos Remote Code Execution Vulnerability (CVSS 8.8) Advisory
Microsoft Office PowerPoint (3 Critical)
- CVE-2026-69678 — Microsoft Office PowerPoint Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-69767 — Microsoft Office PowerPoint Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-69797 — Microsoft Office PowerPoint Remote Code Execution Vulnerability (CVSS 8.8) Advisory
Windows Key Distribution Center (1 Critical)
- CVE-2026-69712 — Windows Key Distribution Center Remote Code Execution Vulnerability (CVSS 8.8) Advisory
Windows Hello (9 Critical)
- CVE-2026-69740 — Windows Hello Elevation of Privilege Vulnerability (CVSS 8.8) Advisory
- CVE-2026-69784 — Windows Hello Elevation of Privilege Vulnerability (CVSS 8.8) Advisory
- CVE-2026-69820 — Windows Hello Elevation of Privilege Vulnerability (CVSS 8.2) Advisory
- CVE-2026-81354 — Windows Hello Elevation of Privilege Vulnerability (CVSS 8.2) Advisory
- CVE-2026-69725 — Windows Hello Elevation of Privilege Vulnerability (CVSS 7.8) Advisory
- CVE-2026-69799 — Windows Hello Elevation of Privilege Vulnerability (CVSS 7.8) Advisory
- CVE-2026-69864 — Windows Hello Elevation of Privilege Vulnerability (CVSS 7.8) Advisory
- CVE-2026-69710 — Windows Hello Elevation of Privilege Vulnerability (CVSS 7.5) Advisory
- CVE-2026-72980 — Windows Hello Security Feature Bypass Vulnerability (CVSS 4.4) Advisory
Windows Media Player (2 Critical)
- CVE-2026-70203 — Windows Media Player Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-72960 — Windows Media Player Remote Code Execution Vulnerability (CVSS 8.8) Advisory
Microsoft WebP Image Extension (1 Critical)
- CVE-2026-70351 — Microsoft WebP Image Extension Remote Code Execution Vulnerability (CVSS 8.8) Advisory
Windows Paint (1 Critical)
- CVE-2026-70586 — Windows Paint Remote Code Execution Vulnerability (CVSS 8.8) Advisory
Graphic Fonts (2 Critical)
- CVE-2026-72986 — Graphic Fonts Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-73018 — Graphic Fonts Remote Code Execution Vulnerability (CVSS 8.8) Advisory
Microsoft Office Word (2 Critical)
- CVE-2026-77504 — Microsoft Office Word Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-81952 — Microsoft Word Remote Code Execution Vulnerability (CVSS 8.8) Advisory
Microsoft Windows Codecs Library (2 Critical)
- CVE-2026-81352 — Web Media Extensions Remote Code Execution Vulnerability (CVSS 8.8) Advisory
- CVE-2026-58599 — HEVC Video Extensions Remote Code Execution Vulnerability (CVSS 7.8) Advisory
Azure Machine Learning (1 Critical)
- CVE-2026-68791 — Azure Machine Learning Information Disclosure Vulnerability (CVSS 8.6) Advisory
Power Automate (1 Critical)
- CVE-2026-65818 — Power Automate Elevation of Privilege Vulnerability (CVSS 8.5) Advisory
Windows Secure Kernel Mode (5 Critical)
- CVE-2026-69846 — Windows Secure Kernel Mode Elevation of Privilege Vulnerability (CVSS 8.2) Advisory
- CVE-2026-69906 — Windows Secure Kernel Mode Elevation of Privilege Vulnerability (CVSS 8.2) Advisory
- CVE-2026-83939 — Windows Secure Kernel Mode Elevation of Privilege Vulnerability (CVSS 8.2) Advisory
- CVE-2026-85921 — Windows Secure Kernel Mode Elevation of Privilege Vulnerability (CVSS 8.2) Advisory
- CVE-2026-69501 — Windows Secure Kernel Mode Elevation of Privilege Vulnerability (CVSS 7.0) Advisory
Windows ALPC (1 Critical)
- CVE-2026-69874 — Windows ALPC Elevation of Privilege Vulnerability (CVSS 8.2) Advisory
Windows Credential Guard (1 Critical)
- CVE-2026-72958 — Windows Credential Guard Elevation of Privilege Vulnerability (CVSS 8.2) Advisory
Windows USB Video Driver (1 Critical)
- CVE-2026-72962 — Windows USB Video Driver Elevation of Privilege Vulnerability (CVSS 8.2) Advisory
Azure Portal (1 Critical)
- CVE-2026-83946 — Azure Portal Spoofing Vulnerability (CVSS 8.2) Advisory
Reliable Multicast Transport Driver (RMCAST) (3 Critical)
- CVE-2026-69530 — Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability (CVSS 8.1) Advisory
- CVE-2026-78449 — Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability (CVSS 8.1) Advisory
- CVE-2026-78450 — Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability (CVSS 8.1) Advisory
Role: DNS Server (2 Critical)
- CVE-2026-69827 — Windows DNS Server Remote Code Execution Vulnerability (CVSS 8.1) Advisory
- CVE-2026-77505 — Windows DNS Server Remote Code Execution Vulnerability (CVSS 8.1) Advisory
IP Helper (1 Critical)
- CVE-2026-72981 — IP Helper Remote Code Execution Vulnerability (CVSS 8.1) Advisory
Windows Deployment Services (2 Critical)
- CVE-2026-72957 — Windows Deployment Services Remote Code Execution Vulnerability (CVSS 7.8) Advisory
- CVE-2026-72954 — Windows Deployment Services Remote Code Execution Vulnerability (CVSS 7.5) Advisory
Microsoft Office Excel (6 Critical)
- CVE-2026-81948 — Microsoft Excel Remote Code Execution Vulnerability (CVSS 7.8) Advisory
- CVE-2026-81949 — Microsoft Excel Remote Code Execution Vulnerability (CVSS 7.8) Advisory
- CVE-2026-81950 — Microsoft Excel Remote Code Execution Vulnerability (CVSS 7.8) Advisory
- CVE-2026-81951 — Microsoft Excel Remote Code Execution Vulnerability (CVSS 7.8) Advisory
- CVE-2026-81953 — Microsoft Excel Remote Code Execution Vulnerability (CVSS 7.8) Advisory
- CVE-2026-81959 — Microsoft Excel Remote Code Execution Vulnerability (CVSS 7.8) Advisory
Windows Virtualization-Based Security (VBS) Enclave (2 Critical)
- CVE-2026-83498 — Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability (CVSS 7.8) Advisory
- CVE-2026-83501 — Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability (CVSS 5.5) Advisory
Windows Virtual Trusted Platform Module (1 Critical)
- CVE-2026-69890 — Windows Virtual Trusted Platform Module Elevation of Privilege Vulnerability (CVSS 7.5) Advisory
Windows Graphics Kernel (1 Critical)
- CVE-2026-73017 — Graphics Kernel Remote Code Execution Vulnerability (CVSS 7.5) Advisory
Virtual Hard Disk (VHD) Miniport Driver (1 Critical)
- CVE-2026-81355 — Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability (CVSS 7.5) Advisory
Microsoft Discovery Studio (1 Critical)
- CVE-2026-62906 — Microsoft Discovery Studio Information Disclosure Vulnerability (CVSS 7.4) Advisory
Microsoft 365 Copilot’s Business Chat (1 Critical)
- CVE-2026-78501 — Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability (CVSS 7.4) Advisory
Microsoft Copilot (1 Critical)
- CVE-2026-55946 — Microsoft Copilot Information Disclosure Vulnerability (CVSS 6.1) Advisory
Product Family Breakdown
| Product Family | Total | Critical | Important |
|---|---|---|---|
| Windows Biometric Service | 64 | 0 | 64 |
| SQL Server | 61 | 5 | 56 |
| Microsoft Office Word | 37 | 2 | 35 |
| Windows DHCP Server | 36 | 2 | 34 |
| Microsoft Office Excel | 32 | 6 | 26 |
| Windows NTFS | 29 | 0 | 29 |
| Windows Win32K | 23 | 0 | 23 |
| Microsoft Standard XPS | 18 | 0 | 18 |
| Windows Spaceport.sys | 17 | 0 | 17 |
| Microsoft Office | 16 | 5 | 11 |
| Microsoft Office SharePoint | 16 | 0 | 16 |
| Windows DNS | 14 | 4 | 10 |
| Windows Print Spooler Components | 12 | 0 | 12 |
| Windows Kernel | 11 | 0 | 11 |
| Windows Error Reporting | 11 | 0 | 11 |
| Microsoft Windows Search Component | 11 | 0 | 11 |
| Windows Device Association Service | 11 | 0 | 11 |
| Skype for Business | 10 | 1 | 9 |
| Microsoft Office PowerPoint | 10 | 3 | 7 |
| Visual Studio Code | 10 | 0 | 10 |
| Microsoft Exchange Server | 9 | 0 | 9 |
| Remote Desktop Client | 9 | 0 | 9 |
| Windows USB Audio Class driver (usbaudio.sys) | 9 | 0 | 9 |
| Windows Remote Desktop Services | 9 | 0 | 9 |
| Windows Hello | 9 | 9 | 0 |
| Windows Audio Service | 8 | 0 | 8 |
| Windows Imaging Component | 8 | 6 | 2 |
| Microsoft Graphics Component | 8 | 4 | 4 |
| Windows Routing and Remote Access Service (RRAS) | 8 | 4 | 4 |
| Microsoft Office Outlook | 8 | 4 | 4 |
| Windows Overlay Filter | 7 | 0 | 7 |
| Windows Remote Access Connection Manager | 7 | 0 | 7 |
| Virtual Hard Disk (VHD) Miniport Driver | 7 | 1 | 6 |
| Microsoft Windows Media Foundation | 6 | 1 | 5 |
| Active Directory Domain Services | 6 | 0 | 6 |
| Windows MIDI Service Module | 6 | 0 | 6 |
| Windows Program Compatibility Assistant Service | 6 | 0 | 6 |
| Windows Modern Device Management (MDM) | 6 | 0 | 6 |
| Windows Shell | 6 | 1 | 5 |
| Windows TCP/IP | 6 | 0 | 6 |
| Windows Services for NFS ONCRPC XDR Driver | 6 | 3 | 3 |
| Windows Installer | 5 | 0 | 5 |
| Windows Connected User Experiences and Telemetry | 5 | 0 | 5 |
| Windows USB Driver | 5 | 0 | 5 |
| Windows Storage Spaces Controller | 5 | 0 | 5 |
| Windows Volume Manager Extension Driver | 5 | 0 | 5 |
| Windows USB Video Driver | 5 | 1 | 4 |
| Windows Secure Kernel Mode | 5 | 5 | 0 |
| Windows Hyper-V | 5 | 3 | 2 |
| Windows Kerberos | 5 | 1 | 4 |
| Microsoft Windows Codecs Library | 4 | 2 | 2 |
| Active Directory Certificate Services (AD CS) | 4 | 0 | 4 |
| Windows iSCSI | 4 | 0 | 4 |
| Windows CD-ROM Driver | 4 | 0 | 4 |
| Windows Image Acquisition | 4 | 0 | 4 |
| Windows Management Instrumentation | 4 | 0 | 4 |
| Windows Bluetooth Service | 4 | 0 | 4 |
| Microsoft Office Access | 4 | 0 | 4 |
| Visual Studio | 4 | 0 | 4 |
| Windows SMB Client | 4 | 0 | 4 |
| Windows Deployment Services | 4 | 2 | 2 |
| Role: DNS Server | 4 | 2 | 2 |
| Windows Secure Socket Tunneling Protocol (SSTP) | 4 | 1 | 3 |
| Windows Failover Cluster | 4 | 2 | 2 |
| .NET | 3 | 0 | 3 |
| Windows Push Notifications | 3 | 0 | 3 |
| Azure Arc | 3 | 2 | 1 |
| Windows File History Service | 3 | 0 | 3 |
| Windows USB Mass Storage Class Driver | 3 | 0 | 3 |
| Microsoft Local Security Authority Server (lsasrv) | 3 | 0 | 3 |
| Windows Cloud Files Mini Filter Driver | 3 | 0 | 3 |
| Volume Manager Driver | 3 | 0 | 3 |
| Windows VOLSNAP.SYS | 3 | 0 | 3 |
| Windows IKE Extension | 3 | 0 | 3 |
| Microsoft Windows Speech | 3 | 0 | 3 |
| Windows Compressed Folder | 3 | 0 | 3 |
| Windows Partition Management Driver | 3 | 0 | 3 |
| Windows Event Logging Service | 3 | 0 | 3 |
| Role: Windows Fax Service | 3 | 0 | 3 |
| Reliable Multicast Transport Driver (RMCAST) | 3 | 3 | 0 |
| Windows Universal Disk Format File System Driver (UDFS) | 3 | 0 | 3 |
| Graphic Fonts | 3 | 2 | 1 |
| Windows Message Queuing | 3 | 1 | 2 |
| Windows Encrypting File System (EFS) | 3 | 0 | 3 |
| Windows Credential Providers | 3 | 0 | 3 |
| Windows ALPC | 3 | 1 | 2 |
| Windows Internet Connection Sharing (ICS) | 3 | 1 | 2 |
| Storage Port Driver | 3 | 0 | 3 |
| Microsoft Windows SCSI Class System File | 3 | 0 | 3 |
| Windows Ancillary Function Driver for WinSock | 2 | 0 | 2 |
| ASP.NET Core | 2 | 0 | 2 |
| Windows Netlogon | 2 | 1 | 1 |
| Windows PowerShell | 2 | 0 | 2 |
| Microsoft Dynamics 365 | 2 | 1 | 1 |
| Microsoft Teams for Android | 2 | 0 | 2 |
| Power Automate | 2 | 1 | 1 |
| Windows GDI+ | 2 | 0 | 2 |
| Windows Universal Plug and Play (UPnP) Device Host | 2 | 0 | 2 |
| Windows Defender Firewall Service | 2 | 0 | 2 |
| Windows Bluetooth Port Driver | 2 | 0 | 2 |
| Microsoft Account | 2 | 0 | 2 |
| Windows Fast FAT Driver | 2 | 0 | 2 |
| Windows Network Connection Broker | 2 | 0 | 2 |
| Windows Message Queuing Queue Manager | 2 | 0 | 2 |
| Windows Remote Desktop Licensing Service | 2 | 0 | 2 |
| Kernel Streaming WOW Thunk Service Driver | 2 | 0 | 2 |
| Windows License Manager | 2 | 0 | 2 |
| Remote Desktop Gateway Service | 2 | 0 | 2 |
| Microsoft COM for Windows | 2 | 0 | 2 |
| Windows Device Association Broker service | 2 | 0 | 2 |
| Windows Power Dependency Coordinator | 2 | 0 | 2 |
| Microsoft JScript | 2 | 0 | 2 |
| Windows Storage | 2 | 0 | 2 |
| Windows Text Shaping | 2 | 0 | 2 |
| Windows NDIS | 2 | 0 | 2 |
| Windows Network File System | 2 | 0 | 2 |
| Windows SMB Server | 2 | 0 | 2 |
| Windows Storage Management Provider | 2 | 0 | 2 |
| Windows Distributed File System (DFS) | 2 | 0 | 2 |
| Windows URL Moniker | 2 | 0 | 2 |
| Windows BitLocker | 2 | 0 | 2 |
| Windows Enterprise App Management | 2 | 0 | 2 |
| Windows RNDIS | 2 | 0 | 2 |
| Windows Work Folder Service | 2 | 0 | 2 |
| Windows Resilient File System (ReFS) | 2 | 0 | 2 |
| Windows HTTP Print Provider | 2 | 1 | 1 |
| Windows Accounts Control | 2 | 0 | 2 |
| Windows Key Distribution Center | 2 | 1 | 1 |
| Microsoft Office Publisher | 2 | 0 | 2 |
| Windows DHCP Client | 2 | 0 | 2 |
| Microsoft Fabric | 2 | 2 | 0 |
| Azure Cosmos DB | 2 | 2 | 0 |
| Azure Logic Apps | 2 | 2 | 0 |
| Windows Media Player | 2 | 2 | 0 |
| Windows Win32 Kernel Subsystem | 2 | 0 | 2 |
| Windows Schannel | 2 | 0 | 2 |
| Windows Credential Guard | 2 | 1 | 1 |
| Windows Core Messaging | 2 | 0 | 2 |
| Windows OLE DB | 2 | 0 | 2 |
| GitHub Copilot and Visual Studio Code | 2 | 0 | 2 |
| Windows Virtualization-Based Security (VBS) Enclave | 2 | 2 | 0 |
| M365 Copilot | 2 | 2 | 0 |
| Azure AI Foundry | 2 | 2 | 0 |
| Microsoft Copilot | 1 | 1 | 0 |
| Windows VHD miniport driver | 1 | 0 | 1 |
| Windows Server | 1 | 0 | 1 |
| Microsoft Trace Data Helper | 1 | 0 | 1 |
| Windows RDP Client | 1 | 0 | 1 |
| XBox Gaming Services | 1 | 0 | 1 |
| Azure Billing | 1 | 1 | 0 |
| Microsoft Discovery Studio | 1 | 1 | 0 |
| Microsoft Entra ID | 1 | 1 | 0 |
| Azure Machine Learning | 1 | 1 | 0 |
| Windows Bind Filter Driver | 1 | 0 | 1 |
| Internet Storage Name Service | 1 | 0 | 1 |
| Microsoft UxTheme Library (uxtheme.dll) | 1 | 0 | 1 |
| Windows DCOM Server | 1 | 0 | 1 |
| Windows Setup Files Cleanup | 1 | 0 | 1 |
| Push Message Routing Service | 1 | 0 | 1 |
| Windows Performance Monitor | 1 | 0 | 1 |
| BranchCache | 1 | 0 | 1 |
| Windows Registry | 1 | 0 | 1 |
| Windows Storage Port Driver | 1 | 0 | 1 |
| Windows Broker Infrastructure Service | 1 | 0 | 1 |
| OpenSSH for Windows | 1 | 0 | 1 |
| Audio Video Control Transport Protocol | 1 | 0 | 1 |
| Windows Kernel Mode Driver | 1 | 0 | 1 |
| Windows LDAP - Lightweight Directory Access Protocol | 1 | 0 | 1 |
| Windows Embedded Mode Service | 1 | 0 | 1 |
| Telnet Client | 1 | 0 | 1 |
| Windows State Repository Service | 1 | 0 | 1 |
| .NET and Visual Studio | 1 | 0 | 1 |
| Windows Device Health Attestation (DHA) | 1 | 0 | 1 |
| Windows Devices Human Interface | 1 | 0 | 1 |
| Windows Microsoft DirectMusic | 1 | 0 | 1 |
| Connected Devices Platform Service (Cdpsvc) | 1 | 0 | 1 |
| Windows Wireless Networking | 1 | 0 | 1 |
| Windows Remote Desktop | 1 | 1 | 0 |
| Windows Camera Frame Server Monitor | 1 | 0 | 1 |
| Windows Online Certificate Status Protocol (OCSP) | 1 | 0 | 1 |
| Microsoft Windows PDF | 1 | 0 | 1 |
| Windows HTTP.sys | 1 | 0 | 1 |
| Windows PrintWorkflowUserSvc | 1 | 0 | 1 |
| Microsoft Install Service | 1 | 0 | 1 |
| Windows exFAT File System | 1 | 0 | 1 |
| Windows Notification | 1 | 0 | 1 |
| Windows Raw Image Extension | 1 | 1 | 0 |
| Windows Host Guardian Service | 1 | 0 | 1 |
| Windows IP Address Management (IPAM) Service | 1 | 0 | 1 |
| Windows Web Platform Storage | 1 | 0 | 1 |
| Windows Secure Boot | 1 | 0 | 1 |
| Windows Direct Show | 1 | 0 | 1 |
| Windows Group Policy | 1 | 0 | 1 |
| HID class driver | 1 | 0 | 1 |
| Windows Link Layer Topology Discovery Protocol | 1 | 0 | 1 |
| Windows Broadcast DVR User Service | 1 | 0 | 1 |
| Windows Container Manager Service | 1 | 0 | 1 |
| Windows DWM Core Library | 1 | 0 | 1 |
| Windows Smart Card | 1 | 0 | 1 |
| RPC Runtime | 1 | 0 | 1 |
| Windows iSCSI Target Service | 1 | 0 | 1 |
| Spring Cloud Azure | 1 | 1 | 0 |
| Windows Wireless Wide Area Network Service | 1 | 0 | 1 |
| Microsoft Container Registry | 1 | 1 | 0 |
| Windows Virtual Trusted Platform Module | 1 | 1 | 0 |
| Windows Media | 1 | 0 | 1 |
| Microsoft WebP Image Extension | 1 | 1 | 0 |
| Azure AI Language | 1 | 1 | 0 |
| Windows AF_UNIX Socket Provider | 1 | 0 | 1 |
| Windows Display Enhancement Service | 1 | 0 | 1 |
| Windows Mobile Broadband | 1 | 0 | 1 |
| Windows Paint | 1 | 1 | 0 |
| Windows Remote Desktop Protocol | 1 | 0 | 1 |
| Windows NFS Portmapper | 1 | 0 | 1 |
| Winsock | 1 | 0 | 1 |
| Microsoft WDAC OLE DB provider for SQL | 1 | 0 | 1 |
| Windows Task Scheduler | 1 | 0 | 1 |
| Windows SMB Server Network Transport Driver (srvnet.sys) | 1 | 0 | 1 |
| Windows Modern Execution Server | 1 | 0 | 1 |
| Windows WebClient Service | 1 | 0 | 1 |
| Active Directory Federation Services (AD FS) | 1 | 0 | 1 |
| IP Helper | 1 | 1 | 0 |
| Windows Volume Shadow Copy | 1 | 0 | 1 |
| Windows USB Hub Driver | 1 | 0 | 1 |
| Windows Autopilot | 1 | 0 | 1 |
| Windows Authentication Methods | 1 | 0 | 1 |
| Windows Management Services | 1 | 0 | 1 |
| Data Sharing Service Client | 1 | 0 | 1 |
| Windows Graphics Kernel | 1 | 1 | 0 |
| Windows GDI | 1 | 0 | 1 |
| Windows Boot Manager | 1 | 0 | 1 |
| Windows Security Center | 1 | 0 | 1 |
| Microsoft Dataverse | 1 | 1 | 0 |
| Azure CycleCloud | 1 | 0 | 1 |
| Xbox | 1 | 0 | 1 |
| Windows Security Health Service | 1 | 0 | 1 |
| Microsoft 365 Copilot’s Business Chat | 1 | 1 | 0 |
| Windows Work Folders | 1 | 0 | 1 |
| Microsoft Authenticator | 1 | 0 | 1 |
| Copilot Studio | 1 | 1 | 0 |
| Azure HDInsights | 1 | 0 | 1 |
| Windows Update Stack | 1 | 0 | 1 |
| Microsoft Azure Active Directory B2C | 1 | 1 | 0 |
| Entra ID | 1 | 1 | 0 |
| Azure Portal | 1 | 1 | 0 |
| Microsoft Azure CLI | 1 | 0 | 1 |
| Windows Resilient File System (ReFS) Deduplication Service | 1 | 0 | 1 |
| Microsoft Authentication Library (MSAL) for Node.js | 1 | 0 | 1 |
| Azure Database for PostgreSQL | 1 | 1 | 0 |
Data sourced from the Microsoft Security Response Center. Mariner (Azure Linux) and Edge (Chromium-based) CVEs are excluded from this summary. Generated by ARETIQ AI.